CWE-232: Improper Handling of Undefined Values
The product does not handle or incorrectly handles when a value is not defined or supported for the associated parameter, field, or argument name.
11 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-20192 — A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE Software could allow an au
- CVE-2025-40775 — DNS message with invalid TSIG causes an assertion failure
- CVE-2025-20314 — A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an una
- CVE-2026-21689 — iccDEV has Type Confusion in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cpp
Recently published
- CVE-2026-21689 — iccDEV has Type Confusion in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cpp
- CVE-2025-20314 — A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an una
- CVE-2025-40775 — DNS message with invalid TSIG causes an assertion failure
- CVE-2025-20192 — A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE Software could allow an au